USA Valids Leak Means 113 Accounts Are Ready to Steal
HEROIC analysts identified a stealer log dump titled "USA VALIDS AnonymousRichard" circulating on Telegram in May 2026. The file contained 113 verified credentials specifically targeting United States-based accounts. Each record includes an email address, a plaintext password, and the URL of the compromised service. The threat actor behind this dump, operating under the alias "AnonymousRichard," specifically curated and validated these US-focused credentials for maximum exploitation potential.
Why Plaintext Passwords from Validated US Accounts Demand Urgent Action
When credentials are both plaintext and validated, they represent the most immediately exploitable form of stolen data. There is no decryption required and no uncertainty about whether the passwords still work. Attackers can log into these 113 accounts within seconds of obtaining the file.
US-based accounts are particularly valuable targets because they are frequently linked to financial services, healthcare portals, government platforms, and enterprise systems that hold sensitive personal and financial data. A single compromised US email account can provide access to tax records, insurance information, and banking credentials.
The targeted nature of this dump, focused exclusively on US accounts, suggests the threat actor is either selling to buyers interested in US-specific fraud or planning targeted attacks against American individuals and organizations.
What Was Exposed in the USA Valids Dump
- Email Addresses — US-based email addresses verified as active and accessible
- Plaintext Passwords — Working passwords confirmed against live services
- URLs — Login pages for US-based services where credentials were captured
Why 113 Validated US Credentials Are a Concentrated Threat
A focused set of 113 validated US credentials is more dangerous than a large, unfiltered dump. Each entry has been tested and confirmed working, meaning the success rate for exploitation approaches 100 percent at the time of release. Attackers do not waste time on dead credentials.
These credentials can be used for targeted identity theft operations, including filing fraudulent tax returns, opening credit accounts, or accessing healthcare records. US consumers face an average cost of over $1,000 per identity theft incident, and validated credentials dramatically accelerate the timeline from breach to fraud.
The curated nature of this dump also makes it attractive for spear-phishing campaigns, where attackers use known-working email credentials to send convincing messages to the victim's contacts, colleagues, and financial institutions.
How Stealer Logs Enable Geo-Targeted Credential Theft
Infostealer malware like RedLine, Raccoon, and Vidar harvests credentials indiscriminately from infected devices. However, threat actors frequently post-process the raw logs, sorting records by country, service type, or domain to create specialized dumps for specific markets.
The "USA VALIDS" label indicates this dump was filtered from a larger stealer log collection, with only US-based credentials retained and then validated against live services. This additional processing makes each record more valuable and more dangerous to the individuals affected.
The malware responsible for these captures typically arrives through phishing emails, infected software downloads, or malicious browser extensions. Victims are rarely aware their credentials have been stolen until unauthorized activity appears on their accounts.
Check If Your US-Based Credentials Were Exposed
If you have a US-based email account and have ever saved login credentials in your web browser, your information may be among the 113 validated records in this dump. Immediate password changes across all accounts using the same or similar passwords are strongly recommended.
Use the HEROIC data breach scanner to search across more than 400 billion compromised records. You can check whether your email address appeared in this US-targeted dump or any other known breach and take immediate steps to protect your identity and accounts.
Breach Breakdown
113 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds